Intelligent WAN 2.0 principles. Pero Gvozdenica, Systems Engineer, pero.gvozdenica@combis.hr Vedran Hafner, Systems Engineer, vehafner@cisco.



Similar documents
Cisco IWAN and Akamai Intelligent Platform : Maximize Your WAN Investment

Verizon Managed SD WAN with Cisco IWAN. October 28, 2015

Cisco Dynamic Multipoint VPN: Simple and Secure Branch-to-Branch Communications

Cisco Group Encrypted Transport VPN: Tunnel-less VPN Delivering Encryption and Authentication for the WAN

BrainDumps

Cisco Passguide Exam Questions & Answers

Network Management for Common Topologies How best to use LiveAction for managing WAN and campus networks

BrainDumps q. Cisco Enterprise Networks Core and WAN Exam

LiveAction Visualization, Management, and Control for Cisco IWAN Overview

LiveAction: GUI-Based Management and Visualization for Cisco Intelligent WAN

Cloud Managed Security with Meraki MX

IWAN Security for Remote Site Direct Internet Access and Guest Wireless

Router Throughput Tests

Visualization, Management, and Control for Cisco IWAN

Ethernet Wide Area Networking, Routers or Switches and Making the Right Choice

Analyze hop-by-hop path, devices, interfaces, and queues Locate and troubleshoot problems

Cisco Unified Access Technology Overview: Converged Access

Securing Networks with Cisco Routers and Switches 1.0 (SECURE)

Delivering Managed Services Using Next Generation Branch Architectures

Cisco WAAS Express. Product Overview. Cisco WAAS Express Benefits. The Cisco WAAS Express Advantage

Managed 4G LTE WAN: Provide Cost-Effective Wireless Broadband Service

Network as an Sensor & Enforcer

Cisco Virtualization Experience Infrastructure: Secure the Virtual Desktop

Cisco and Visual Network Systems: Implement an End-to-End Application Performance Management Solution for Managed Services

Cisco Actualtests Exam Questions & Answers

Cisco EXAM Enterprise Network Unified Access Essentials. Buy Full Product.

Redefine Network Visibility in the Data Center with the Cisco NetFlow Generation Appliance

Data Center Network Evolution: Increase the Value of IT in Your Organization

Passguide q

LiveAction: GUI-Based Management and Visualization for Cisco Intelligent WAN

Transform Your Business and Protect Your Cisco Nexus Investment While Adopting Cisco Application Centric Infrastructure

SDN Applications in Today s Data Center

Increase Simplicity and Improve Reliability with VPLS on the MX Series Routers

2013 ONS Tutorial 2: SDN Market Opportunities

Cisco TrustSec How-To Guide: Guest Services

Cisco SR 520-T1 Secure Router

Network Virtualization Network Admission Control Deployment Guide

IINS Implementing Cisco Network Security 3.0 (IINS)

Cisco Wide Area Application Services (WAAS) Software Version 4.0

How To Use The Cisco Wide Area Application Services (Waas) Network Module

Implementing Cisco IOS Network Security

Intelligent WAN. Technology Design Guide

A Mock RFI for a SD-WAN

Truffle Broadband Bonding Network Appliance

Cisco Application Networking for BEA WebLogic

Cisco Unified Network Services: Overcome Obstacles to Cloud-Ready Deployments

Virtualized Network Services SDN solution for enterprises

WAN Optimization. Riverbed Steelhead Appliances

An Introduction to Service Containers

Virtual Leased Line (VLL) for Enterprise to Branch Office Communications

Cisco NetFlow Generation Appliance (NGA) 3140

Cisco Integrators Cisco Partners installing and implementing the Cisco Catalyst 6500 Series Switches

MDM Integration with Cisco Identity Service Engine. Secure Access How -To Guides Series

The Advantages of Cloud Services

Private Cloud Solutions Virtual Onsite Data Center

Threat-Centric Security for Service Providers

WAN Optimization Integrated with Cisco Branch Office Routers Improves Application Performance and Lowers TCO

Intelligent WAN. Technology Design Guide

Cisco Application Networking for IBM WebSphere

November Defining the Value of MPLS VPNs

PCI Compliance for Branch Offices: Using Router-Based Security to Protect Cardholder Data

The Next Generation Network:

Cisco Router and Security Device Manager (SDM)

SDN and NFV in the WAN

Configuring a Site-to-Site VPN Tunnel Between Cisco RV320 Gigabit Dual WAN VPN Router and Cisco (1900/2900/3900) Series Integrated Services Router

Chapter 1 The Principles of Auditing 1

Cisco Easy VPN on Cisco IOS Software-Based Routers

Cisco Security Manager 4.2: Integrated Security Management for Cisco Firewall, IPS, and VPN Solutions

Designing for Cisco Internetwork Solutions

Reliable high throughput data connections with low-cost & diverse transport technologies

Sprint Global MPLS VPN IP Whitepaper

Virtual Privacy vs. Real Security

Implementing Cisco Quality of Service QOS v2.5; 5 days, Instructor-led

Virtualized Network Services SDN solution for service providers

Cisco ASA and Cloud Web Security: Best-in-Class Network Security Combined with Best-in-Class Web Security

Cisco Integrated Services Routers Performance Overview

EVOLVED DATA CENTER ARCHITECTURE

VPLS lies at the heart of our Next Generation Network approach to creating converged, simplified WANs.

Cisco TrustSec for PCI Scope Reduction Verizon Assessment and Validation

Cisco TrustSec Solution Overview

A ZK Research Whitepaper. October Cisco s Branch Infrastructure Powers the HYBRID WAN

Licenses are not interchangeable between the ISRs and NGX Series ISRs.

MPLS: Key Factors to Consider When Selecting Your MPLS Provider

Best Effort gets Better with MPLS. Superior network flexibility and resiliency at a lower cost with support for voice, video and future applications

XenMobile Integration with Cisco Identity Service Engine. Secure Access How -To Guides Series

Best Practices for deploying unified communications together with SIP trunking connectivity

Leveraging SDN and NFV in the WAN

Providing a work-your-way solution for diverse users with multiple devices, anytime, anywhere

IPv6 Fundamentals, Design, and Deployment

Remote Voting Conference

Cisco and EMC Solutions for Application Acceleration and Branch Office Infrastructure Consolidation

White Paper: Virtual Leased Line

5 Key Reasons to Migrate from Cisco ACE to F5 BIG-IP

MPLS: Key Factors to Consider When Selecting Your MPLS Provider Whitepaper

Transcription:

Intelligent WAN 2.0 principles Pero Gvozdenica, Systems Engineer, pero.gvozdenica@combis.hr Vedran Hafner, Systems Engineer, vehafner@cisco.com

Then VS Now

Intelligent WAN: Leveraging the Any Transport Secure WAN Transport and Internet Access Hybrid WAN Transport IPsec Secure Branch MPLS (IP-VPN) Private Virtual Private Direct Internet Access Secure WAN transport for private and virtual private cloud access Leverage local Internet path for public cloud and Internet access Internet Public Increased WAN transport capacity and cost effectively Improve application performance (right flows to right places)

Intelligent WAN Solution Components AVC Internet Private 3G/4G-LTE Virtual Private Branch WAAS PfR MPLS Public Transport Independent Intelligent Path Control Application Optimization Secure Connectivity Consistent operational model Simple provider migrations Scalable and modular design DMVPN IPsec overlay design Application best path based on delay, loss, jitter, path preference Load balancing for full utilization of all bandwidth Improved network availability Performance Routing (PfR) AVC: Application monitoring with Application Visibility and Control Per-tunnel Hierarchical QoS WAAS: Application Acceleration and bandwidth savings WAAS: Intelligent Edge Caching with Akamai Connect Certified strong encryption Comprehensive threat defense with ASA and IOS firewall/ips Web Security (CWS) for scalable secure direct Internet access

Flexible Secure WAN Design Over Any Transport Dynamic Multipoint VPN (DMVPN) Transport-Independent Simplifies WAN Design Easy multi-homing over any carrier service offering Single routing control plane with minimal peering to the provider Flexible Dynamic Full-Meshed Connectivity Consistent design over all transports Automatic site-to-site IPsec tunnels Zero-touch hub configuration for new spokes Secure Proven Robust Security Certified crypto and firewall for compliance Scalable design with highperformance cryptography in hardware Internet WAN ASR 1000 ISR-G2/4xxx MPLS Branch ASR 1000 Data Center

What is Performance Routing (PfR)? Tooling for Intelligent Path Control Performance Routing (PfR) provides additional intelligence to classic routing technologies to track the performance of, or verify the quality of, a path between two devices over a Wide Area Networking (WAN) infrastructure to determine the best egress or ingress path for application traffic... Data Center BR MC BR Cisco IOS technology DSL Cable Two components: Master controller and border router MC+BR Branch

Make Your IWAN Application Aware Add Cisco AVC Users/ Machines Proliferation of Devices Public Private Branch DC/Headquarters No Probes Smart Capacity Planning Business Aligned Privacy Enforcement Cisco AVC Rich data collection using NetFlow v9/ipfix No additional hardware (and included in AX license) Easy to integrate into many reporting tools Better use of costly bandwidth Per-branch and per-application level reporting No need for complex IP and port ACLs See inside HTTP flows to identify specific applications 60% of IT Professionals Cite Performance as Key Challenge for

Cisco WAAS Enhancing User Experience and WAN Efficiency Problem Solution Application latency WAN bandwidth inefficiencies Reduce load Data redundancy elimination (DRE), compression, and TCP optimization Application optimization Fewer protocol messages and metadata caching 4 3 Bandwidth (Mbps) Latency (Seconds) 160 Reduction in bandwidth 120 2 80 Reduction in latency Application bandwidth natively Application bandwidth with Cisco WAAS 1 40 Application latency natively Application latency with Cisco WAAS 0 0 Application Application Bandwidth Latency

Akamai Connect Caching & Prepositioning Caches HTTP Content Prepositioning of internet and Private cloud content, including dynamic URLs like YouTube MPLS (IP-VPN) Private Virtual Private Branch Cached & Prepositioned content improves application response time dramatically Akamai Intelligent Platform Akamai Connect works over WAN and directly from the Internet Public WAAS Optimization + Akamai Connect improves both Private and Public performance

Direct Internet Access What I can do with Internet pipe on Branch?

Intelligent WAN: Secure Connectivity Securing the network and users Secure WAN Transport Branch MPLS (IP-VPN) Private Virtual Private Secure Internet Access Internet Public Two areas of concern Protecting the network from outside threats with data privacy over provider networks Protecting user access to Public and Internet services; malware, privacy, phishing,

Secure Direct Internet Access Web Security (CWS) Branch ISR Connector to CWS Firewall towers WAN2 (Internet) IWAN IPsec VPN for Private Traffic WAN1 (IP-VPN) CWS Private Secure Public and Internet Access Public Web Filtering, Access Policy, Malware Detect Internet

CWS Guest Access CWS Guest Policy Create Guest Filters 13

TrustSec WAN Support Propagation WLC SGACL Finance ISR G2 ASR 1000 ISE MACSec SGT L2 Frame Catalyst Branch Network GET-VPN Nexus 5500 IPSec-VPN Sales Admin DM-VPN Flex-VPN Catalyst 6500 Nexus 7000 Data Center Inline SGT tagging on all ASR1000 and ISR G2 built-in LAN interfaces except 8xx Series Inline tagging between ASR 1000 and ISR G2 for: IPSec DMVPN FlexVPN GET-VPN

Intelligent WAN: An Architectural and Systems Approach IWAN is a Solution Architecture Solves a network problem Use Case Driven Systems Development Approach Prescribed. Tested. Interoperable. Bounded Scope and Complexity Enables Automation and Quality NEW! Delivers Business Outcomes Reduce WAN costs. Increase bandwidth Improve and Protect application performance Direct Internet Access Guest Access Offload IT Simplification (Cost reduction)

Cisco IWAN Management On-Prem Management Specialized Management -Based Management Prime Infrastructure 2.2 / 3.0 End-to-End Assurance of Application Experience Application Aware Network Performance Management Automates Deployment and Lifecycle Management Single-pane view of IWAN IWAN deployment workflows Plug and Play DMVPN, QoS, AVC deployment and monitoring PfR v3 in Q1 2015 License includes IWAN App and APIC- EM controller! Integrates with Cisco AVC and PfR Monitor and analyze application traffic End-to-end flow visualization Flow & App-based Troubleshooting Fix and Verify in Realtime Eliminates manual building of WANs Automated SD-WAN orchestration Centralized hybrid WAN management Quick config updates and IOS upgrades Leverages onepk and REST APIs

Prime Infrastructure 2.2 for IWAN IWAN workflow wizard with PnP Template-based IWAN configs PfRv3 Domain, MC and BR AVC One-Click provision QoS Provisioning Single or Dual Router Branch CVD-based, Customizable AVC Readiness Assessment AVC, QoS, PfR Visibility Leverages APIC EM services

Cisco Prime IWAN Automation and Orchestration Evolution Prime Capacity Planning, Troubleshooting, Change control Traditional Management Systems Cisco IWAN Apps IWAN Transport Security PKI Automation Intelligent Path Control PnP Provisioning Application Experience Partners (future) Apps Evolutio n REST APIs APIC-EM Services (Partial) PKI Svc NetFlow Svc Network Svc Events Svc Inventory Svc PnP Svc APIC-EM OnePK/Openflow Device Abstraction Layer CLI

Q & A 20